← Prev in month ← Prev in thread

How to provide SAML assertions in RESTful services

From
Moehrke, John (GE Healthcare) <>
Date
2010-06-25T15:21:58+00:00
ID
Thread
How to provide SAML assertions in RESTful services
In defining a RESTful AP to a healthcare service, that
really needs a SAML identity assertion to enable access controls on the
service-provider (RESTful service provider). When using SOAP, this is easily
done with WS-Security, but I am struggling with how to specify how a SAML
assertion would be carried to the relying-party on the RESTful request. The browser-sso-profile
doesn’t work well for non-browser transactions. Is there a recommendation
on how to do this? 

 

One solution that I have not yet researched is to use OAuth
as a wrapper.

 

 

John Moehrke

Principal Engineer: Interoperability and Security

GE Healthcare 

 

M +1 920 912 8451



www.gehealthcare.com

productsecurity.gehealthcare.com

 

3200
  N. Grandview Blvd 

Mail stop:  WT-881

Waukesha, WI 
 53188

 

GE imagination at work
← Prev in month ← Prev in thread